Skip to content

Commit 7d50fe6

Browse files
RafaelGSSaduh95
authored andcommitted
doc: mention DEPENDENCY custom field for H1 reports
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: #64634 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
1 parent 46b1177 commit 7d50fe6

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

doc/contributing/security-release-process.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,8 @@ The current security stewards are documented in the main Node.js
6767
* [ ] 3\. **Assigning Severity and Writing Team Summary:**
6868
* [ ] Assign a severity and write a team summary on HackerOne for the reports
6969
chosen in the `vulnerabilities.json`.
70+
* [ ] If a report targets a Node.js dependency, such as `undici` or `llhttp`,
71+
make sure to update the `DEPENDENCY` custom field on HackerOne.
7072
* Run `git node security --sync` to update severity and summary in
7173
`vulnerabilities.json`.
7274

0 commit comments

Comments
 (0)